Saved
Audit Workspace
FY2026 ITGC Audit
JA
Junior Auditor
Clear review note — AC-02 testing workpaper
Michelle Carter has left a review note. Confirm which access extract you tested against.
Open testing workpaper
Action required
Respond to management — SR-IT-001 finding disputed
Daniel Brooks has challenged the finding. Maintain, accept or request further evidence. Your written justification is the graded submission in Project Lab.
Open finding
Decision needed
Access testing — AC-01, AC-02, AC-03 complete
Submitted 30 Jun 2026 · Under review by Michelle Carter
Complete
Change management testing — CH-01, CH-02 complete
Submitted 1 Jul 2026 · Reviewed
Complete
Phase 4 — Application control (APP-01) Excel analysis submitted
3 exceptions identified · Submitted through Project Lab
Complete
Overall progress
71%
5 of 7 phases complete
Controls tested
7/7
All 7 controls tested
Open findings
1
SR-IT-001 — medium
Exceptions found
5
Across all controls
Engagement details
EngagementFY2026 IT General Controls Audit
Period1 Jan 2026 – 30 Jun 2026
ManagerMichelle Carter
AuditorJunior IT Auditor
SystemsStarRich ERP · HR · Entra ID · CRM
StandardIIA Global Internal Audit Standards 2025
Control status summary
PassAC-01 · OP-012 controls
ExceptionAC-02 · AC-03 · CH-01 · CH-02 · APP-015 controls
Overall control rating pending executive summary (Phase 7). Expected: Effective with Exceptions.
Total in scope
7
Effective
2
With exceptions
5
Open findings
1
Access controls — AC
2 exceptions
AC-01
New user access provisioning
Documented manager approval required before access is provisioned
Daniel Brooks
Per event
Effective
AC-02
Terminated user access removal
IT access disabled promptly following confirmed employee termination
Daniel Brooks
Per event
Exception
AC-03
Privileged access review
Admin accounts reviewed quarterly for continued appropriateness
Daniel Brooks
Quarterly
Exception
Change management — CH
2 exceptions
CH-01
Production change approval
All production changes approved before deployment
James Okafor
Per event
Exception
CH-02
Change testing evidence
Documented UAT or testing evidence required prior to production deployment
James Okafor
Per event
Exception
Operations & application controls
1 exception (APP-01)
OP-01
Backup monitoring
Scheduled backups monitored; failures detected, investigated and remediated
James Okafor
Daily
Effective
APP-01
High-value invoice approval
Invoices exceeding $25,000 require secondary approval before payment
Rachel Vance
Per transaction
Exception
IPE validation required — action taken
ER-002 was extracted 15 May 2026. Audit period ends 30 June 2026. Population was incomplete — TWALKER (joined 19 May) and LNGOZI (joined 1 June) were absent. ER-002b (refreshed 30 June) was requested and received. All access testing uses ER-002b.
Resolved
Access & identity evidence
ER-001
Employee population
50 employees · FY2026 full year · HR system export
HR system
30 Jun 2026
Accepted
ER-002
User access population — stale IPE issue
49 accounts · Extracted 15 May 2026 · Missing TWALKER, LNGOZI
StarRich ERP
15 May 2026
Not used
ER-002b
User access population — refreshed Used for testing
51 accounts · Extracted 30 Jun 2026 · Complete
StarRich ERP
30 Jun 2026
Accepted
ER-003
Terminated employees listing
7 terminations · FY2026 · All via Email to IT Shared Mailbox
HR system
30 Jun 2026
Accepted
ER-004
Access approval records
8 approval records · New joiners and admin accounts
IAM system
30 Jun 2026
Accepted
ER-005
Privileged access listing
4 admin/elevated accounts · Q1 and Q2 review status
IAM system
30 Jun 2026
Exception — Q2 reviews missing
Change management evidence
ER-006
Change tickets
5 tickets · Jan–Jun 2026 · 2 exceptions (CR-2026-047, CR-2026-052)
ServiceNow
30 Jun 2026
2 exceptions
Operations evidence
ER-009
Backup monitoring dashboard
7 daily records · 11–17 Jun 2026 · 1 failure with successful rerun
Monitoring system
17 Jun 2026
Control effective
ER-010
Incident record — INC-2026-017
17 Jun backup failure · Alert at 02:36 · Resolved 09:14 same day
ServiceNow
17 Jun 2026
Accepted
Application control evidence
ER-011
Invoice population (Excel workbook)
150 invoices · Jan–Jun 2026 · 3 exceptions identified in Excel analysis
StarRich ERP
30 Jun 2026
3 exceptions
ER-013
ERP approval configuration
$25,000 secondary approval threshold · Admin > AP Settings · Correctly configured
StarRich ERP
30 Jun 2026
Accepted
Access testing
Change management
Operations
Review note — Michelle Carter · 30 Jun 2026 14:23

Please confirm which extract version was used for access testing. ER-002 (extracted 15 May 2026) is missing two accounts created after that date. Ensure all testing references ER-002b (30 June extract).

Why employers need this skill
Pathward — IT Auditor I
SOX ITGC testing including user access management and logical securityjob-boards.greenhouse.io/pathward ↗
UniFirst — IT Internal Auditor
Execute SOX ITGC testing across all domains including user accessunifirst.referrals.selectminds.com ↗
City of Hope — IT Internal Auditor
ITGC testing including access management, walkthroughs, data analyticscityofhopejobs.org ↗
Sample testing · Population: ER-002b (51 accounts) · Sample: 3
All samples pass
#EmployeeEmp IDAccountApproval refApproval dateAccess grantedOn time?Evidence refResultComment
1Marcus WebbSR1055MWEBBAPR-2026-00108 Apr 202610 Apr 2026YesER-002b, ER-004
2Lena NgoziSR1062LNGOZIAPR-2026-00401 Jun 202603 Jun 2026YesER-002b, ER-004
3Tom WalkerSR1061TWALKERAPR-2026-00319 May 202622 May 2026YesER-002b, ER-004
AC-01 conclusion: 3/3 samples pass. Control operating effectively.
Sample testing · Source: ER-003 (7 terminations) × ER-002b · Sample: 3
1 exception — Emily Parker
#EmployeeEmp IDTerminatedAccountAcc. statusDisabledDays to disableEvidence refResultComment
1Emily ParkerSR104202 Jun 2026EPARKERActive (stale) / Disabled (ER-002b)17 Jun 202615 daysER-003, ER-002b
2Jake QuinnSR100822 Mar 2025JQUINNDisabled24 Mar 20252 daysER-003, ER-002b
3Victor ZhangSR101326 Mar 2026VZHANGDisabled27 Mar 20261 dayER-003, ER-002b
AC-02 conclusion: 1/3 samples fail. Exception: Emily Parker — 15-day delay. Finding raised: SR-IT-001.
Quarterly review testing · Source: ER-005 (4 privileged accounts) · Full population
Exception — Q2 review not completed (2 accounts)
AccountAccount holderAccess levelQ1 review dateQ1 reviewerQ2 review dateQ2 reviewerQ2 statusResultComment
JOKAFOR_ADMJames OkaforAdmin31 Mar 2026M. CarterNOT COMPLETED
DBROOKS_ADMDaniel BrooksAdmin28 Mar 2026M. CarterNOT COMPLETED
MCARTERMichelle CarterElevated31 Mar 2026VP Technology30 Jun 2026VP TechnologyCOMPLETED
SYSADMIN01Service accountAdmin31 Mar 2026J. Okafor30 Jun 2026J. OkaforCOMPLETED
AC-03 conclusion: Q2 quarterly review not completed for JOKAFOR_ADM and DBROOKS_ADM. No evidence found. Exception noted.
Complete testing in Excel workpaper (Access Testing tab), then submit through Project Lab
Why employers need this skill
Pathward
Identify control deficiencies and communicate findings clearlyjob-boards.greenhouse.io/pathward ↗
UniFirst
Develop practical, value-added recommendations; demonstrate professional scepticismunifirst.referrals.selectminds.com ↗
City of Hope
Document findings with clarity and precision; collaborate with stakeholders to validate findingscityofhopejobs.org ↗
SR-IT-001
Delayed removal of terminated user access
Medium severity Open AC-02
Emily Parker (SR1042, Finance) was terminated on 2 June 2026. Her ERP account (EPARKER) remained active and accessible until 17 June 2026 — 15 calendar days after confirmed termination.
AC-02 requires that IT system access is disabled promptly following confirmed employee termination. There is no defined SLA at present; "prompt" is the stated standard.
HR termination notifications are sent by email to a shared IT mailbox. The notification for Emily Parker was received but not converted into an access-removal ticket. No ticket was raised for account EPARKER.
A former employee retained active ERP credentials for 15 days post-termination. During this window, unauthorised access to financial transactions, vendor records and accounts payable data was possible. No login was detected in the ERP access log after 2 June, but the risk existed throughout the 15-day period.
1. Automate the HR-to-IT notification via system integration — replace email to shared mailbox with a triggered ticket in the ITSM system.
2. Define a formal access-removal SLA (recommended: 24 hours).
3. Implement a weekly exception report identifying accounts belonging to terminated employees that remain active beyond the SLA.
DB
Daniel Brooks — Identity & Access Manager
15 July 2026 · 10:34
"We acknowledge the delay in removing Emily Parker's access. However, I reviewed the ERP access log and can confirm that Emily did not log into the system at any point after her termination date of 2 June. There is therefore no evidence that any unauthorised access occurred. Given this mitigating factor, we believe the risk is minimal and that raising a formal finding is disproportionate to the actual risk realised."
Auditor note: The absence of detected login activity is a genuine mitigating fact — it can reduce severity from High to Medium. However, it does not eliminate the control failure. The control failed regardless of outcome. Maintaining the finding at Medium severity is the professionally defensible position. Submit your response and justification through Project Lab.
Your written justification is the graded submission in Project Lab Phase 5 — not this button click.
Why employers need this skill
Pathward
Perform validation testing over remediation plans; conduct follow-up testingjob-boards.greenhouse.io/pathward ↗
City of Hope
Validate remediation efforts and conduct follow-up testingcityofhopejobs.org ↗
UniFirst
Monitor issued findings and confirm remediationunifirst.referrals.selectminds.com ↗
Time jump
28 September 2026 — 90 days after finding issued
Management has marked SR-IT-001 as Remediated. New termination evidence is available below for your re-test.
Management's stated remediation actions
Declared remediated
1
Automated HR-to-IT ticket creation
HR termination feed now automatically creates an access-removal ticket in ServiceNow on confirmation of termination. The shared mailbox route is no longer used.
2
24-hour SLA defined and implemented
Formal access-removal SLA of 24 hours from confirmed termination. IT operations team is accountable.
3
Weekly exception report
Weekly report identifies active accounts belonging to terminated employees. Exceptions escalated to IT Operations Manager.
James Okonkwo SR1071
Finance
4.4 hours
Within 24h SLA
Terminated
01 Aug 2026
Ticket created
01 Aug 15:23
Account disabled
01 Aug 19:47
Sarah Mills SR1072
Sales
3.5 hours
Within 24h SLA
Terminated
05 Aug 2026
Ticket created
05 Aug 11:02
Account disabled
05 Aug 14:30
Ravi Patel SR1073
HR
26.1 hours
Borderline — just over SLA
Terminated
12 Aug 2026
Ticket created
12 Aug 09:15
Account disabled
13 Aug 11:22
Chen Wei SR1074
Technology
65.6 hours
Clear SLA breach — 3 days
Terminated
19 Aug 2026
Ticket created
19 Aug 16:40
Account disabled
22 Aug 10:15
Amy Jackson SR1075
Marketing
3.6 hours
Within 24h SLA
Terminated
26 Aug 2026
Ticket created
26 Aug 08:55
Account disabled
26 Aug 12:30
Re-test summary
3 of 5 cases within the 24-hour SLA. 2 exceptions: Ravi Patel (26.1h — borderline) and Chen Wei (65.6h — clear breach). Submit your conclusion and written rationale through Project Lab Phase 6.
Your written rationale is the graded submission in Project Lab — not this button.
StarRich FY2026 IT General Controls Audit Report
Audit objective
Assess whether key IT controls supporting financial reporting and critical technology processes are appropriately designed and operating effectively across StarRich's primary systems during the period 1 January to 30 June 2026.
Scope — auto-populated from Phase 1
StarRich ERP StarRich HR Microsoft Entra ID Change management (CH-01, CH-02) Backup monitoring (OP-01) Invoice approval (APP-01)
Controls tested — auto-populated from Phase 3–4
Control IDDescriptionOwnerResultFinding
AC-01New user access provisioningDaniel BrooksEffective
AC-02Terminated user access removalDaniel BrooksExceptionSR-IT-001
AC-03Privileged access reviewDaniel BrooksException
CH-01Production change approvalJames OkaforException
CH-02Change testing evidenceJames OkaforException
OP-01Backup monitoringJames OkaforEffective
APP-01High-value invoice approvalRachel VanceException
Findings — auto-populated from Phase 5
SR-IT-001 Delayed removal of terminated user access Medium Partially Remediated
Remediation status — auto-populated from Phase 6
SR-IT-001: Partially Remediated. 3 of 5 re-test cases within the new 24-hour SLA. Process improved materially but not yet operating consistently within requirements.
Overall control rating — select in Project Lab Phase 7
Effective
Effective with Exceptions
Needs improvement
Ineffective
Executive summary — complete in Project Lab Phase 7 (max 150 words)
Your executive summary, key recommendation, and final audit conclusion are submitted through Project Lab Phase 7. This workspace shows you what has been auto-populated so you can write a precise, evidence-based summary referencing the actual results above.
Available after Phase 7 is submitted in Project Lab
Note: None of these tools are required for this project. This library explains what they are, how they map to what you've done here, and what to say in an interview. You'll learn the real tools on the job when your employer licenses them.
Audit management platforms — this Workspace is modelled on these
Optro (formerly AuditBoard) — OpsAudit
Used by more than 50% of the Fortune 500. This StarRich Workspace is modelled on OpsAudit — the navigation, evidence requests, workpapers, review notes, findings module and remediation panel all replicate how OpsAudit actually works. Watch this to see the real platform and confirm how it maps to what you've been using.
Watch: How to use AuditBoard — beginners (2025) AuditBoard tutorial & demo (2025)
What to say in an interview: "I completed an end-to-end ITGC audit engagement in a platform modelled on Optro's OpsAudit. I managed evidence requests, documented workpapers with prepared-by and reviewed-by fields, raised a formal finding, responded to management pushback and conducted remediation testing — all within the audit management workflow."
TeamMate+ (Wolters Kluwer)
Dominant in banking, public sector and UK government organisations. Same workflow as OpsAudit — different interface. Key difference: check-in/check-out on workpapers means only one person can edit at a time.
Watch: TeamMate+ agile audit execution Take a fresh look at TeamMate+
Data analytics tools
ACL Analytics / Diligent HighBond: Does what you did in Phase 4 — filter 150 invoices to find the 3 exceptions — but scriptable, repeatable across millions of rows, and integrated with the audit management platform. Same analytical thinking, faster tool. No free access exists anywhere. You will learn it when your employer licenses it. Enterprise-only, $20,000–$50,000+/year.
Vulnerability scanners (Nessus, Qualys, Rapid7): As an IT auditor, you review the scan output and test the patch management control — you do not run the scanner. The scanner is operated by the vulnerability management or security team. You assess whether scans run on schedule, whether critical findings were remediated within policy SLA, and whether exceptions were documented. That is auditing the control — not running the tool.
Certifications to target next
CISA
CISA — Certified Information Systems Auditor (ISACA)
The primary IT audit credential. Required or strongly preferred at senior level. Opens doors at Big Four, FTSE companies and Fortune 500 internal audit teams. ISACA YouTube ↗
CIA
CIA — Certified Internal Auditor (IIA)
Broader internal audit credential. Strong complement to CISA for those targeting audit management roles.
CISM
CISM — Certified Information Security Manager (ISACA)
For IT auditors targeting the cybersecurity audit or GRC path. More technical and security-focused than CISA.
ACA
ACA / ACCA (UK candidates)
UK-specific. Combines finance and audit; strong route into Big Four internal audit or finance-adjacent IT audit roles. Respected by FTSE and financial services employers.